Skip to main content

Port Details

Port
5985
Transport
TCP
Service
WinRM
IANA service name
wsman
Range
User port (1024-49151)
Related ports

Security Exposure

MITRE ATT&CK T1021.006 describes adversaries using valid accounts over WinRM, which lets a user run an executable, modify the Registry and modify services on the remote system. The technique is listed under the Lateral Movement tactic. A listener on 5985 that is reachable from untrusted networks accepts authentication attempts from anyone who can reach it.

Hardening

  • +Allow 5985 only from management subnets or jump hosts using Windows Firewall scope rules.
  • +Prefer the HTTPS listener on 5986 when traffic crosses untrusted networks.
  • +Restrict who can connect with the session configuration permissions and keep the default administrators-only access.
  • +Keep the TrustedHosts list minimal and use Kerberos authentication in domains.
  • +Disable the WinRM service on hosts that are not managed remotely.

Monitoring

Collect WinRM and PowerShell Remoting event logs and alert on remote sessions from hosts outside the management tier.

Tools for Auditing and Monitoring WinRM

Evil-WinRM

Open Source
Penetration Testing Tools

WinRM shell for Linux and Windows that supports authorized remote management, file transfers, and PowerShell execution during security reviews.

LicenseLGPL-3.0-only
PlatformLinux, Windows

Sysmon

Free
SIEM Tools

Windows Sysinternals service that logs detailed process, network, and file activity to the event log.

LicenseProprietary
PlatformWindows
SIEM Tools

Microsoft enterprise EDR covering Windows, macOS, Linux, and mobile from one console.

LicenseProprietary
PlatformWindows, macOS, Linux, iOS, Android, Web

Frequently Asked Questions

What is the difference between port 5985 and 5986?→

Microsoft documents 5985 as the default WinRM HTTP port and 5986 as the default HTTPS port.

Is WinRM on port 5985 unencrypted?→

Microsoft states that, regardless of HTTP or HTTPS, WinRM encrypts all PowerShell Remoting traffic after initial authentication. The initial exchange depends on the authentication protocol, and Basic authentication provides no encryption, so HTTPS adds TLS protection and server authentication.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 5985 is not guaranteed to be WinRM. Exploited-in-the-wild data from the CISA KEV catalog (CC0).